http-rs / http-rs/http-types

Unmaintained, insecure and obsoleted dependencies

Open
#529 8 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
209
Forks
91
PR merge metrics
No merged PRs in 30d

Description

Some dependencies have significant issues and do not pass the `cargo audit`:
```
Crate: aes-soft
Version: 0.6.4
Warning: unmaintained
Title: `aes-soft` has been merged into the `aes` crate
Date: 2021-04-29
ID: RUSTSEC-2021-0060
URL: https://rustsec.org/advisories/RUSTSEC-2021-0060
Dependency tree:
aes-soft 0.6.4
└── aes 0.6.0
└── aes-gcm 0.8.0
└── cookie 0.14.4
└── http-types 2.12.0
```

```
Crate: aesni
Version: 0.10.0
Warning: unmaintained
Title: `aesni` has been merged into the `aes` crate
Date: 2021-04-29
ID: RUSTSEC-2021-0059
URL: https://rustsec.org/advisories/RUSTSEC-2021-0059
Dependency tree:
aesni 0.10.0
└── aes 0.6.0
└── aes-gcm 0.8.0
└── cookie 0.14.4
└── http-types 2.12.0
```

```
Crate: cpuid-bool
Version: 0.2.0
Warning: unmaintained
Title: `cpuid-bool` has been renamed to `cpufeatures`
Date: 2021-05-06
ID: RUSTSEC-2021-0064
URL: https://rustsec.org/advisories/RUSTSEC-2021-0064
Dependency tree:
cpuid-bool 0.2.0
└── polyval 0.4.5
└── ghash 0.3.1
└── aes-gcm 0.8.0
└── cookie 0.14.4
└── http-types 2.12.0
```

```
Crate: instant
Version: 0.1.13
Warning: unmaintained
Title: `instant` is unmaintained
Date: 2024-09-01
ID: RUSTSEC-2024-0384
URL: https://rustsec.org/advisories/RUSTSEC-2024-0384
Dependency tree:
instant 0.1.13
├── fastrand 1.9.0
│ └── futures-lite 1.13.0
│ ├── http-types 2.12.0
```

```
Crate: stdweb
Version: 0.4.20
Warning: unmaintained
Title: stdweb is unmaintained
Date: 2020-05-04
ID: RUSTSEC-2020-0056
URL: https://rustsec.org/advisories/RUSTSEC-2020-0056
Dependency tree:
stdweb 0.4.20
└── time 0.2.27
└── cookie 0.14.4
└── http-types 2.12.0
```

Contributor guide

Open the contributing guide

Research direction

Start by running cargo audit and inspect the dependency declarations and lockfile for the reported aes-soft, aesni, cpuid-bool, instant, and stdweb paths. Trace which direct dependencies bring them in, then update or replace those dependencies while preserving compatibility; done means cargo audit no longer reports these advisories.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.